Is it ok to "--force-renewal" every months?

Explaining the differences mentioned above for the next person to read this thread:

  1. By default, Certbot runs a cronjob every day. It only renews the Certificates that exceed the renew time (with a default of 60 days). In the future this will be based on the Automatic Renewal Information payloads.

  2. --force-renewal will tell certbot to force a renewal regardless of the expiry date. You can certainly run that every 30 days to force new certificates, but if it fails you will not be able to recover automatically until the next invocation. You can not run this daily, because that will break rate limits.

  3. So the standard solution for this situation is what @9peppe and @rg305 mentioned above:

5 Likes

thank you very much for the explanation, this is much appreciated.

2 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.